🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company is migrating its MySQL-based payment application to Amazon RDS. To comply with PCI DSS requirement 3.4, you must ensure that stored primary account numbers (PAN) are unreadable while making no application-code changes. The chosen approach must also provide centralized key management and support automatic key rotation with minimal operational effort. Which solution best satisfies these objectives?

  • Launch the RDS instance without encryption, store PAN in plaintext, and restrict access using IAM roles and VPC security groups.

  • Hash each PAN with unsalted SHA-1 in the application and save the hash to an Amazon S3 bucket that has versioning disabled.

  • Enable encryption at rest when creating the Amazon RDS MySQL instance, selecting a customer managed AWS KMS key that is configured for annual rotation, and store PAN directly in the database.

  • Modify the application to encrypt PAN with 3DES before inserting it into RDS, keeping the encryption key in local EC2 configuration files.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot